3 ms·
Hey HN, I made this for myself, because my blog is served as static HTML via GitHub Pages and it's hard to test locally because all of my absolute paths break
by clusmore 8y ago
Hey HN,
I made this for myself, because my blog is served as static HTML via GitHub Pages and it's hard to test locally because all of my absolute paths break (links, imgs, scripts, css, etc.). I tried using the Python module http.server, but it doesn't support dropping the file extension (e.g. /about instead of /about.html). Thought somebody else doing the same might find this useful.
- csunbird 8y agoDid you test it against relative path(s) ? For example, what if "../" is included in the file path ? It can be used to escape the root folder and traverse arbitrarily in the host file system.
- clusmore 8y agoThat's a great question. Although I don't encourage anybody to expose this to any network they don't trust, it was a concern. I was previously passing the incoming path directly to ServeFile[1] which handles this, although I have since put in a filepath.Clean... I've tested this in browsers and with curl and it looks okay, I'll take a closer look at this though. [1]: https://golang.org/pkg/net/http/#ServeFile https://golang.org/pkg/net/http/#ServeFile
- ddebernardy 8y agoFYI GitHub Pages is merely running Jekyll (jekyllrb.com) with a couple of commonly used plugins. If you want to test you site locally you'll be better off using that.
- clusmore 8y agoThat's a fair point. Previous iterations of my GitHub Pages used Jekyll and I used that at the time to test it, but I recently switched to plain-old-HTML and honestly it didn't occur to me that Jekyll would still work for testing it. Having said that, installing Jekyll[1] has quite a few steps and requires quite a few dependencies which I don't typically have installed, so this is a bit easier for me to distribute to my various machines. [1]: https://help.github.com/articles/setting-up-your-github-pages-site-locally-with-jekyll/ https://help.github.com/articles/setting-up-your-github-page...